xbox-scene.com - your xbox news information source
Quick Links: Main Forums | Xbox360 Forums | Xbox1 Forums | PS3 Forums
Xbox-Scene Forum Help  Search Xbox-Scene Forums   Xbox-Scene Forum Members   Xbox-Scene Calendar

Special Limited Offer: SuperNews Unlimited Usenet Access, Unlimited Speed for $11.99
256-bit SSL, 350 Days Retention, 30 Connections - Join Today! - ONLY $11.99

Support this site - buy the X-Scene Tshirt $17.95

Welcome Guest ( Log In | Register )

 Forum Rules Rules
3 Pages V  1 2 3 >  
Reply to this topicStart new topic
> 360 Flash Dump Tool V0.1
Xbox-Scene
post May 28 2007, 08:28 AM
Post #1


Memba Numero Uno
Group Icon

Group: Admin
Posts: 4177
Joined: 17-May 02
From: Yurop
Member No.: 1
Xbox Version: unk
360 version: unknown



360 Flash Dump Tool V0.1
Posted by Iriez | May 28 03:28 EST | News Category: Xbox360
 
This tool will allow you to decrypt and extract various parts of a XBox360 flash dump. The flash is devided into 2 major parts

1) The Cx sections (CB,CD,CE & 0,1 or 2 CF & CG sections).
CB, CPU bootup
CD, unpacker for CE
CE, contains the HV and Kernel in a .cab archive
CF&CG are upgrade patches

The tool will extract and decrypt sections CB, CD, CE. Additionally it will extract the .cab file in section CE. This can be opened with winrar and the content (xboxkrnl.img) extracted. The first 256K of xboxkrnl.img is the Hypervisor, the remainder is the 2.0.1888 Kernel.

2) The Flash File System.

The tool expects a dump to contain the data (512 bytes) followed by the ECC (16 bytes). The ECC bytes are used to locate FS entries & identify the version.

The tool consists of the exe and CxKey.txt. CxKey.txt is delivered with 32 '0's and they should be replaced with the key obtained from the 1BL. After all the fuss about AACS keys recently it seems risky to put the key in the exe Wink The Cx sections extracted from a dump will only decrypt correctly if the correct hex digits are inserted in the CxKey.txt file

To do to it

Add support for CF & CG sections
Patch and re-encrypt pairing data in CB and CF


News-Source: xboxhacker.net


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ravo5002
post May 28 2007, 08:33 AM
Post #2


X-S Member
*

Group: XS-BANNED
Posts: 72
Joined: 21-May 06
Member No.: 283163
Xbox Version: none
360 version: none



sweet, so we basicly can look for mistakes in the as src since its uncrypted?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
zest
post May 28 2007, 08:56 AM
Post #3


X-S Young Member
*

Group: Members
Posts: 52
Joined: 24-June 02
Member No.: 895
Xbox Version: v1.0
360 version: v1 (xenon)





I would guess so. This is nice and with the recent "setback" fresh in mind i hope that something good is going to come out from this. Keep up the good work! \o/
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Knasen
post May 28 2007, 09:54 AM
Post #4


X-S Freak
*****

Group: Members
Posts: 1124
Joined: 9-September 03
Member No.: 61522
Xbox Version: v1.1
360 version: v1 (xenon)



So, is this something new that perhaps could help the homebrew scene or is it just "old" news thats getting more available to the public ?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
CreisoN
post May 28 2007, 12:22 PM
Post #5


X-S Young Member
*

Group: Members
Posts: 30
Joined: 11-June 04
Member No.: 124883



Seems thats the 1šstep to have a hacked bios in xbox360.
Will us in a future b able to unban those banned 360īs i bet yes!:D
Imagine a 360 serial generator and we able to replace the 360 key for a good one not banned!:)
I hope im not that Wrong !
Peace u all!
rolleyes.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
xlokix
post May 28 2007, 12:33 PM
Post #6


X-S Enthusiast


Group: Members
Posts: 14
Joined: 24-March 05
Member No.: 208554



QUOTE(Knasen @ May 28 2007, 05:30 AM) *

So, is this something new that perhaps could help the homebrew scene or is it just "old" news thats getting more available to the public ?


This is something new. It will help the homebrew scene downgrade from 4552 kernel to the 4532 kernel. I hope. smile.gif

Quote from tmbinc:

"That means: If you know how to calculate the CF pairing data, you could modify the "expected sequence" value there (this, however, should be verified by someone.) And to be able to calculate that data, you need the "per-box-key". But if you have that, you could set the number of a 4532 to those of a 4552, and it should boot again."




This post has been edited by xlokix: May 28 2007, 12:39 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
GuntherMP5
post May 28 2007, 01:36 PM
Post #7


X-S Member
*

Group: XS-BANNED
Posts: 63
Joined: 30-June 06
Member No.: 288220
Xbox Version: unk
360 version: unknown



Will this allow to read the key requested for the DVD drive from the 360 CPU?

I still need to try to fix an old bricked sammy.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TheSpecialist
post May 28 2007, 01:49 PM
Post #8


X-S Senior Member
**

Group: Members
Posts: 289
Joined: 8-October 05
Member No.: 250903



QUOTE(xlokix @ May 28 2007, 02:09 PM) *

This is something new. It will help the homebrew scene downgrade from 4552 kernel to the 4532 kernel. I hope. smile.gif

Let's hope that it finally results in something like that, yes. We created the tool for several reaons, one reason is of course that the future version of the tool will be able to use the info in CE+CF/CG to create the 'true' kernel image. Currently, we can only dump the true kernel from mem for kernels that are exploitable, so not 4552 for example ('true' kernel is base kernel+patches applied). This tool will hopefully soon be able to dump such 4552 'true' kernel from a flash image so we can analyse newer kernels as well and maybe find exploits in that too.

Another reason is that we want more insight in that 'pairing' process that tmbinc describes. And hopefully, the availability of the tool will help other hackers with a 'jump' start. Just run the tool and you have all interesting code sections decrypted and ready for analysis ! smile.gif

QUOTE(CreisoN @ May 28 2007, 01:58 PM) *

Seems thats the 1šstep to have a hacked bios in xbox360.
Will us in a future b able to unban those banned 360īs i bet yes!:D

I don't think unbanning will ever be possible I'm afraid. The console ID is linked to a so called 'console certificate'. That certificate is signed with the MS private key. If these don't match, the x360 won't boot. And since we don't have the MS private key, we can't create a certificate for another console ID. Even if we'd hack the x360 so that it wouldnt care less about an unmatching certificate, it would be incredibly easy for MS to ask for a valid certificate via LIVE.

This post has been edited by TheSpecialist: May 28 2007, 02:02 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
acsutton
post May 28 2007, 02:40 PM
Post #9


X-S Enthusiast


Group: Members
Posts: 12
Joined: 19-August 06
Member No.: 295542



I have a quick nooby question. When the spring update is applied, does it not update the kernel. I was holding off on updating in hopes that I would be able to run homebrew someday on 4552, but if it doesn't even matter I would go ahead and update.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
CreisoN
post May 28 2007, 02:41 PM
Post #10


X-S Young Member
*

Group: Members
Posts: 30
Joined: 11-June 04
Member No.: 124883



Hum ok !
If we able to get the key from a MB with this we maybe able to replace from a 3 redlight console that is not banned like we do with the drives?
It is like pick the key from the broken consoles that i know it is not banned and put this key in my from
ex: it is like my console now is that one not banned for MS isnt it?
like b4 we able to replace the key only with the drives it save lots of peaple to insted lose the hol console insted and save atlest the drive what is very inportant smile.gif
Now we might b able to replace the key also in the MB what u think ?
My question is it possible ?
Peace u ALL!
smile.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
bLiTz 2k
post May 28 2007, 03:01 PM
Post #11


X-S Member
*

Group: Members
Posts: 61
Joined: 1-December 05
From: NYC
Member No.: 261099
Xbox Version: v1.0
360 version: v1 (xenon)





QUOTE(CreisoN @ May 28 2007, 07:58 AM) *

Seems thats the 1šstep to have a hacked bios in xbox360.
Will us in a future b able to unban those banned 360īs i bet yes!:D
Imagine a 360 serial generator and we able to replace the 360 key for a good one not banned!:)
I hope im not that Wrong !
Peace u all!
rolleyes.gif



You're very wrong...

QUOTE(CreisoN @ May 28 2007, 10:17 AM) *

Hum ok !
If we able to get the key from a MB with this we maybe able to replace from a 3 redlight console that is not banned like we do with the drives?
It is like pick the key from the broken consoles that i know it is not banned and put this key in my from
ex: it is like my console now is that one not banned for MS isnt it?
like b4 we able to replace the key only with the drives it save lots of peaple to insted lose the hol console insted and save atlest the drive what is very inportant smile.gif
Now we might b able to replace the key also in the MB what u think ?
My question is it possible ?
Peace u ALL!
smile.gif



You're thinking a little too far ahead for what this tool's intentions are. This isnt going to get you unbanned anytime soon, as its purpose is mainly for kernel analysis. Sure at some point there may be a way to do something of an eeprom swap such as what was done on the original xbox, but thats highly unlikely, at least for a very very very long time. I think you need to keep things in perspective, and if you want Live so bad buy another 360.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
The Prankster
post May 28 2007, 03:20 PM
Post #12


X-S Senior Member
**

Group: Members
Posts: 169
Joined: 16-April 07
From: New Hampshire
Member No.: 338792
Xbox Version: v1.6
360 version: v1 (xenon)



This is a good reason to get infectus... This is awesome news, good job!

Cmon CreisoN... stop resorting everything to 'The solution for banning.' You = banned, which in turn = permanent. There are other threads for that 'Never-gonna-happen-theory-stuff.'

Cheers.

This post has been edited by The Prankster: May 28 2007, 03:24 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
BrooksyX
post May 28 2007, 03:20 PM
Post #13


X-S Senior Member
**

Group: Members
Posts: 193
Joined: 16-November 06
Member No.: 311653
Xbox Version: v1.3
360 version: v2 (zephyr)





This is great news, hopefully it will lead to bigger and better things soon.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
BLKMGK
post May 28 2007, 03:35 PM
Post #14


X-S Enthusiast


Group: Members
Posts: 15
Joined: 13-July 06
Member No.: 289849



This looks much like some of the early steps with the PSP. With this the workings of the flash can be better understood and documented, a baby step but a huge one! Have to have the tools and understanding before anything can be built. The PSP community started out much the same way as I recall, this is very good news indeed!

Certificates were mentioned for Live!, are they also signing the flash images? In other words does any minor modification to a flash image invalidate it? Is the code that does this checking hardwired somehow or perhaps just in the installer? I'd be surprised if there's no crypto check on the image, hopefully it can be worked around and enough understanding of the workings gained to allow for unsigned code to be run. For me, personally, that's the holy grail! Something like XBMC or the 360MAME kinds of code is what I'm after rather than a cheap Linux box.

Seeing efforts like this is VERY encouraging and I'm glad I purchased a box with the old firmware just to hold onto. 2 actually but I upgraded the one with the less supported DVD drive so I could play games on Live! heh. I know others whoi have done the same thing, and glad they did I'm betting.

If the community can get to the point where the PSP development is now - unsigned code, custom fetures, blah blah, I will be damned happy, I hope that unsigned code execution is the shared goal.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
CreisoN
post May 28 2007, 04:13 PM
Post #15


X-S Young Member
*

Group: Members
Posts: 30
Joined: 11-June 04
Member No.: 124883



Hum iC well apriciate bLiTz 2k your clarification hopefully some day in a future things become more flexible like
eeprom swap or key swap.
I really dont care about to play on live, the only thing i like about live r the demos and videos from the upcoming releases dont think worths pay to play with others i already paid for the console:well thats my point of view.
But im not wondering to get a new 360 to have it back like b4. smile.gif
Anyway apriciate your atention Thank u very much.
Peace U ALL!
rolleyes.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post





3 Pages V  1 2 3 >
Reply to this topicStart new topic

 

Lo-Fi Version Time is now: 21st November 2009 - 01:23 PM